FILEMembers
FILE

Sandbox Clears It, 26 Engines Don't: Allaple's Acrobat HTML Ruse

A dropper disguised as an Adobe Acrobat DC resource file racks up 26 of 77 VirusTotal detections for trojan.allaple, yet a single sandbox run cleared the identical hash as harmless with 99% confidence. That static-vs-dynamic gap, inside a thin three-file cluster ranging from 3KB to 3030KB, is the campaign's most concrete finding.

Sep 18, 2026, 14:36 (UTC+9)Last seenSep 18, 2026Severity54ByCTX TeamIOC74MITRE12RegionsUS

A dropper posing as an Adobe Acrobat DC interface resource carries the file name "index.html" and sits, according to its own embedded path reference, inside C:\Program Files\Adobe\Acrobat DC\Acrobat\WebResources\Resource0\index.html. Twenty-six of 77 engines on VirusTotal flag it as trojan.allaple. A single sandbox run on the same file, however, returned a "harmless" verdict at 99% confidence.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence